All the latest UK technology news, reviews and analysis

Veracode intros free cross-site scripting scan service

by Phil Muncaster

31 Jan 2011

Be the first to comment

  • Tweet this

Security company Veracode has launched a free cross-site scripting (XSS) scanning service designed to enable developers to eradicate the errors responsible for more than half of the word's web application vulnerabilities.

XSS vulnerabilities typically allow hackers to inject malicious script into web pages by circumventing traditional validation systems. This can result in hijacked user sessions, web site defacement or user redirects to malicious sites.

The Veracode Free XSS Detection Service can be used for any Java-based application up to 20MB in size with a limit of one application per email address.

Customers will need to register an account with Veracode and supply metadata including build version before submitting for a scan.

The company will then provide a detailed report including remediation steps where appropriate and free access to Veracode's e-learning courses on XSS, said Veracode.

"XSS flaws are the most prevalent and the easiest to fix. There is no reason why apps should be built with XSS errors," said Veracode chief executive Matt Moynahan.

"Developers care about high quality code, but sometimes they are either not given the right specs or are not properly trained."

Moynahan added that Veracode is able to scan huge volumes of code quickly thanks to the cloud-based nature of the service.

"You can expect more free offerings from us in the future to showcase the power of the cloud," he added.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

37%

0%

11%

52%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Availability & Capacity Lead

About Us WorldPay provides a globally connected, locally...

Change & Configuration Administrator

About Us WorldPay provides a globally connected, locally...

SQL Server Developer - SSIS - Zurich

SQL Server Developer - Our client, an international...

IT Technical Service Delivery Manager / ITIL / Reigate - 65K

IT Technical Service Delivery Manager / ITIL / Reigate...

To send to more than one email address, simply separate each address with a comma.